CVE-2024-37632: Critical severity totolink a3700r firmware vulnerability
Published Jun 13, 2024
·Updated
TOTOLINK A3700R V9.1.2u.616520211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .
Affected Software
2 affected components
All of the following
Totolink A3700R Firmware=9.1.2u.6165_20211012
Totolink A3700R Firmware
Event History
Jun 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-37632?
CVE-2024-37632 has been classified with high severity due to potential remote exploitation risks.
2
How do I fix CVE-2024-37632?
To fix CVE-2024-37632, upgrade the firmware of the TOTOLINK A3700R to the latest version provided by the vendor.
3
What is the impact of CVE-2024-37632?
The impact of CVE-2024-37632 includes the possibility of a stack overflow during authentication, potentially allowing remote attackers to execute arbitrary code.
4
Which software versions are affected by CVE-2024-37632?
CVE-2024-37632 affects the TOTOLINK A3700R firmware version 9.1.2u.6165_20211012.
5
Can CVE-2024-37632 be exploited remotely?
Yes, CVE-2024-37632 can be exploited remotely through the vulnerable login authentication process.